First published: Thu Jul 09 2020(Updated: )
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Bitbucket | >=4.9.0<7.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Bitbucket Server vulnerability is CVE-2020-14171.
The severity of CVE-2020-14171 is medium with a CVSS score of 6.5.
The affected software version range for CVE-2020-14171 is from version 4.9.0 before version 7.2.4.
CVE-2020-14171 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack.
Yes, it is recommended to upgrade Bitbucket Server to version 7.2.4 or later to fix CVE-2020-14171.